SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 204,000 - 226,000 / annual
Hello Heart is an AI-driven cardiac prevention platform that predicts and prevents heart attacks before they occur—identifying risk up to 10 days in advance compared to traditional clinical models. The company serves over 80% of large U.S. health plans and hundreds of employers, demonstrating measurable impact with 47% reduction in inpatient hospital days and ~$1,800 annual savings per member.
As Senior Counsel, Data Governance, you will own Hello Heart's legal and regulatory strategy for data use, reporting to the Chief Compliance and Privacy Officer. You will lead negotiations on how the company can collect, use, share, retain, reuse, and apply AI to data while ensuring agreements provide necessary rights for operations, innovation, and growth while meeting regulatory and contractual obligations. You will have direct exposure to the C-suite and senior executives, partnering closely with leaders across Sales, Technology, Product, Security, and other functions on high-impact business decisions.
This is an owner-operator role. You will not simply advise teams; you will negotiate, build, implement, maintain, run, monitor, audit, and remediate programs and controls within your scope.
Key responsibilities include: leading negotiations on data rights across client and partner agreements (BAAs, DPAs, data use agreements, data sharing agreements) covering data use, ownership, secondary use, AI training, retention, deletion, and downstream use; leading day-to-day operation of Hello Heart's Privacy Program under HIPAA and state privacy requirements; leading the AI governance program including interpretation of federal and state AI laws, governance frameworks, risk assessments, and responsible AI controls; translating legal and regulatory requirements into practical policies, controls, and implementation plans; building systems and controls for data governance including data maps, classification standards, contractual obligation repositories, and vendor reviews; partnering with Product, Engineering, Security, and other teams to implement privacy and AI requirements; leading privacy, data, and AI risk and incident management; conducting compliance monitoring, audits, and regulatory inquiries; and building policies, playbooks, training, and executive reporting.
REQUIREMENTS:
- 8+ years of legal experience with substantial healthcare regulatory, privacy, and compliance experience in a HIPAA-regulated organization (healthcare experience required)
- Significant experience negotiating complex data rights with sophisticated enterprise clients and partners, including large health plans and healthcare organizations; ability to independently lead difficult negotiations involving data use, ownership, AI rights, secondary use, retention, deletion, and de-identification
- Experience operating healthcare privacy and compliance programs, including regulatory interpretation, incident and breach response, risk assessment, monitoring, auditing, and remediation
- Strong compliance judgment and owner-operator mindset with ability to move from legal interpretation to practical implementation
- Advanced AI fluency and automation capability; extensive use of AI in substantive legal and compliance work, ability to automate workflows and build AI agents
- Experience with AI governance, including emerging AI laws, risk assessments, approval workflows, inventories, and responsible AI controls
- Exceptional judgment, executive presence, and communication skills for high-stakes negotiations
- Active license to practice law and membership in good standing with a U.S. state bar
Nice to have: International privacy and data protection experience; privacy or AI governance certifications (CIPP/US, CIPM, AIGP); experience building programs at growth-stage companies; experience managing client trust and security questionnaires.